Skip to content

SafePal vulnerabilities

Cryptocurrency hardware wallet vendor SafePal appears in our reporting in the context of a data breach affecting approximately 39,798 customers due to an authorization flaw in an order-tracking plugin. The primary incident involves threat actors stealing personal order information such as names, emails, shipping addresses, and phone numbers, while the company states that wallet credentials, private keys, or payment information were not compromised. Although specific CVE details are absent, defenders should focus on supply chain risks and monitoring third-party plugin vulnerabilities in this context.

Azərbaycanca: SafePal, kriptovalyuta aparat cüzdanı təchizatçısı, hesabatlarımızda sifariş izləmə plaginindəki avtorizasiya qüsuru səbəbindən təxminən 39,798 müştərinin şəxsi məlumatlarının ifşa olunduğu məlumat sızıntısı ilə bağlı görünür. Əsas hadisə təcavüzkarların ad, e-poçt, ünvan və telefon nömrələri kimi sifariş məlumatlarını oğurlamasıdır, lakin şirkət cüzdan etimadnamələri və ya ödəniş məlumatlarının təsirlənmədiyini bildirir. Bu kontekstdə müdafiəçilər, xüsusi CVE təfərrüatları olmasa da, təchizat zənciri risklərinə və üçüncü tərəf plaginlərinin monitorinqinə diqqət yetirməlidir.

This hub is built from skopnix's own reporting on SafePal: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.